Related Threat Clusters
-
Iranian APT MuddyWater Uses Chaos Ransomware as a False Flag for Espionage
In early 2026, the Iranian APT group MuddyWater, affiliated with the Ministry of Intelligence and Security, executed a sophisticated cyber operation disguised as a Chaos ransomware attack. Utilizing social engineering…
17 articles · Updated May 7, 2026 -
MuddyWater Targets Critical Infrastructure in Israel and Egypt
MuddyWater, an Iran-aligned cyberespionage group, has conducted a targeted campaign against critical infrastructure in Israel and Egypt from September 2024 to March 2025. The group focused on sectors such as…
2 articles · Updated December 3, 2025 -
MuddyWater APT Launches New Rust Malware Against Israeli Targets
The Iranian APT group MuddyWater has intensified cyber-espionage activities in early 2026, specifically targeting Israeli government and infrastructure. They have introduced a new Rust-based remote access trojan named…
25 articles · Updated February 24, 2026 -
MuddyWater APT Uses Rust-Based Implants in Middle East Espionage Campaign
The Iran-linked MuddyWater APT group has launched a spear-phishing campaign targeting various sectors in the Middle East, including diplomatic, maritime, financial, and telecom entities. The campaign employs icon…
5 articles · Updated January 12, 2026 -
Iranian Cyber Espionage Targets US Academics and Policy Experts
Between June and August 2025, a previously unidentified Iranian cyber actor, dubbed UNK_SmudgedSerpent, conducted targeted phishing attacks against US academics and foreign policy experts. The campaign aimed to steal…
1 article · Updated November 10, 2025 -
MuddyWater Targets Israel with MuddyViper Malware
Iran-linked threat actor MuddyWater has launched a campaign against multiple Israeli sectors using a new backdoor called MuddyViper. The attacks also included one confirmed target in Egypt, employing custom tools to…
2 articles · Updated December 2, 2025 -
Iranian APT UNK_SmudgedSerpent Targets US Policy Experts with Phishing Attacks
Between June and August 2025, the Iranian-linked APT UNK_SmudgedSerpent conducted targeted phishing campaigns against US academics and foreign policy experts. The group employed techniques such as credential theft and…
5 articles · Updated November 10, 2025 -
Iranian Hackers Target U.S. Policy Experts with Phishing Attacks
Between June and August 2025, a cyber group identified as UNK_SmudgedSerpent targeted U.S. academics and foreign policy experts focused on Iran. The attackers initiated contact through seemingly benign conversations to…
5 articles · Updated November 7, 2025
Recent Intelligence Reports
- Iranian cyber espionage disguised as a Chaos Ransomware attack — Securityaffairs.Co · May 6, 2026
- MuddyWater hackers use Chaos ransomware as a decoy in attacks — Bleepingcomputer · May 6, 2026
- MuddyWater hackers use Chaos ransomware as a decoy in attacks — Bleepingcomputer · May 6, 2026
- Iran — Infosecurity-Magazine · May 6, 2026
- Iranian MuddyWater APT Targets Israeli Government and Infrastructure With Advanced Rust ... — Rescana · February 24, 2026
- Hackers Are Using RustyWater Malware Against Prominent Middle East Targets — Techjuice.Pk · January 12, 2026
- Iran-linked MuddyWater APT deploys Rust — Csoonline · January 12, 2026
- CloudSEK warns Muddy Water APT using Rust implants in spearphishing on Middle East ... — Industrialcyber.Co · January 10, 2026